{"id":"CVE-2026-64870","summary":"MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation","details":"MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied download_url and download_callback_url values to requests.get without equivalent trusted-host and redirect validation, allowing an authenticated workspace user to make the server request internal, loopback, link-local, or cloud metadata URLs. A fix is present on the v2 branch but has not yet been included in a published release.","aliases":["GHSA-7xxm-gqxv-ph3v"],"modified":"2026-08-12T03:51:33.766665918Z","published":"2026-07-30T17:01:18.102Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64870.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-918"]},"references":[{"type":"ADVISORY","url":"https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-7xxm-gqxv-ph3v"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/64xxx/CVE-2026-64870.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-64870"},{"type":"FIX","url":"https://github.com/1Panel-dev/MaxKB/commit/a96a4fc17051d80e5b90a632ad8ec851d7d24b58"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/1panel-dev/maxkb","events":[{"introduced":"c96de7a5f536909aef37fae92f97f62798eb1373"},{"fixed":"fd6141e662582e88a41edbb7f6f89f4539e3e5dd"},{"fixed":"a96a4fc17051d80e5b90a632ad8ec851d7d24b58"}],"database_specific":{"extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.10.4-lts"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["v2.10.2-lts","v2.10.3-lts","v2.10.1-lts","v2.10.0-lts","v2.9.2","v2.9.1","v2.9.0","v2.8.1","v2.8.0","v2.7.0","v2.6.1","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.2","v2.0.1","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-64870.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N"}]}